Latest CVE Feed
-
7.2
HIGHCVE-2002-0219
Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via large command line argument.... Read more
- EPSS Score: %0.15
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0209
Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled, allows remote attackers to determine the real IP address of a web server with a half-closed session, which causes ACEdirector to send ... Read more
Affected Products : alteon_acedirector- EPSS Score: %6.75
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0217
Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on other web clients via (1) the Title field or a Private Message Box or (2) the image field parameter in pmlite.php.... Read more
Affected Products : xoops- EPSS Score: %1.29
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0224
The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.... Read more
- EPSS Score: %19.46
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0198
Buffer overflow in plDaniels ripMime 1.2.6 and earlier, as used in other programs such as xamime and inflex, allows remote attackers to execute arbitrary code via an attachment in a long filename.... Read more
- EPSS Score: %5.63
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-1056
Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary script... Read more
- EPSS Score: %16.38
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0206
index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers to execute arbitrary PHP code by specifying a URL to the malicious code in the file parameter.... Read more
Affected Products : php-nuke- EPSS Score: %0.22
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0230
Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message.... Read more
Affected Products : faq-o-matic- EPSS Score: %4.38
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2002-0184
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via special characters in the -p (prompt) argument, which are not properly expanded.... Read more
- EPSS Score: %0.21
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2002-0202
PaintBBS 1.2 installs certain files and directories with insecure permissions, which allows local users to (1) obtain the encrypted server password via the world-readable oekakibbs.conf file, or (2) modify the server configuration via the world-writeable ... Read more
Affected Products : paintbbs- EPSS Score: %0.07
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0214
Compaq Intel PRO/Wireless 2011B LAN USB Device Driver 1.5.16.0 through 1.5.18.0 stores the 128-bit WEP (Wired Equivalent Privacy) key in plaintext in a registry key with weak permissions, which allows local users to decrypt network traffic by reading the ... Read more
Affected Products : intel_pro_wireless_2011b_lan_usb_device_driver- EPSS Score: %0.08
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0228
Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or ... Read more
Affected Products : msn_messenger- EPSS Score: %28.61
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0215
Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an error message.... Read more
Affected Products : agora.cgi- EPSS Score: %8.20
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0171
IRISconsole 2.0 may allow users to log into the icadmin account with an incorrect password in some circumstances, which could allow users to gain privileges.... Read more
Affected Products : irisconsole- EPSS Score: %1.53
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0223
Infopop UBB.Threads 5.4 and Wired Community Software WWWThreads 5.0 through 5.0.9 allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends in a different extension.... Read more
- EPSS Score: %0.86
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0231
Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname.... Read more
Affected Products : mirc- EPSS Score: %1.80
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2002-0197
psyBNC 2.3 beta and earlier allows remote attackers to spoof encrypted, trusted messages by sending lines that begin with the "[B]" sequence, which makes the message appear legitimate.... Read more
Affected Products : psybnc- EPSS Score: %0.87
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2002-0196
GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root.... Read more
Affected Products : cwpapi- EPSS Score: %0.44
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2002-0210
setlicense for TOLIS Group Backup and Restore Utility (BRU) 17.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/brutest.$$ temporary file.... Read more
Affected Products : bru- EPSS Score: %0.14
- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2002-0201
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.... Read more
Affected Products : cyberstop_web_server- EPSS Score: %3.04
- Published: May. 16, 2002
- Modified: Apr. 03, 2025